OTP Bypass Attacks

OTP bypass attacks defeat one-time-password authentication without ever knowing the user's password. The principal vectors are SIM swap (porting the victim's MSISDN to an attacker SIM), SS7 SMS interception, malware on the device that reads incoming OTPs, and adversary-in-the-middle phishing kits that relay the OTP in real time. Because all of these break SMS-based MFA, security guidance increasingly recommends FIDO2/WebAuthn or app-based push approval for high-value accounts.

Categories: Core NetworkSignalingIdentity and Subscriber

OTP Bypass Attacks in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place OTP Bypass Attacks in the wider telecom-security picture, review IAMF, MSC, SMS, SMSC, SRI and VoLTE — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.